Responsible Security Disclosure
SACAR welcomes good-faith reports that help protect its public website and users. This notice does not authorise security testing. Testing requires prior written permission and an agreed scope.
How to report
Send a concise initial report to security@sacar.world containing the affected URL, the date and time, the observed behaviour, the likely impact and safe reproduction steps. Do not include personal data, credentials, exploit code or confidential material in the first message. SACAR will provide a secure channel if additional material is required.
Please do not
- Access, alter, delete, download or exfiltrate data that is not your own.
- Use social engineering, phishing, denial of service, malware, automated high-volume scanning or physical intrusion.
- Disrupt service, establish persistence or move beyond the minimum necessary to demonstrate the issue.
- Publicly disclose an unresolved issue, or demand payment as a condition of non-disclosure.
Our response
SACAR aims to acknowledge a credible report within seven working days, assess priority, communicate through an approved channel and remediate proportionately. This notice does not promise a reward, create employment or waive any legal right.